hirly

GEICO

Principal, SOX and MAR

Bethesda, MD · New York City, NY

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at GEICO first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.6M live jobs from 190,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Lead / management
Country
US
Work mode
On-site / unstated
First seen by hirly
27 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

Why Join GEICO?

At GEICO, we offer a rewarding career where your ambitions are met with endless possibilities.

Every day we honor our iconic brand by offering quality coverage to millions of customers and being there when they need us most. We thrive on relentless innovation to exceed our customers' expectations while making a real impact on local communities nationwide.

Founded in 1936, GEICO is a member of the Berkshire Hathaway family of companies and one of the largest auto insurers in the United States. When you join our company, we want you to feel valued, supported, and proud to work here. That's why we offer the GEICO Pledge: Great Company, Great Culture, Great Rewards, and Great Careers.

Principal, SOX and MAR

The Principal, SOX serves as the senior execution lead and technical subject matter expert within the SOX Program Management Office (PMO), accountable for driving day-to-day execution, governance, documentation quality, stakeholder coordination, and continuous improvement of GEICO’s Sarbanes-Oxley and NAIC Model Audit Rule compliance programs under the direction of the Director, SOX PMO.

The Principal partners closely with process owners and key stakeholders, including IT leadership, Internal Audit, and External Audit, to help ensure that Internal Control over Financial Reporting (ICFR) remains effective, scalable, and risk-aligned in support of management’s assertions under Sections 302 and 404 of Sarbanes-Oxley and Section 16 of the NAIC Annual Financial Reporting Model Regulation (Model #205). This role serves as a catalyst for strategic transformation and continuous improvement across the SOX program.

Role in Context

The Principal operates within the SOX PMO as a management governance and execution role. Process and control owners remain accountable for control design, execution, evidence, certification, and remediation. The SOX PMO establishes and administers the program framework and standards. Internal Audit independently tests controls and provides independent assurance.

The Principal is authorized to manage routine program execution and enforce approved SOX PMO standards, while escalating material scoping decisions, methodology changes, deficiency classifications, unresolved stakeholder matters, and other risk-significant judgments to the Director, SOX PMO.

Key Responsibilities

1. SOX Program Execution and Governance

  • Coordinate execution alignment with the parent company’s consolidated SOX program, including applicable methodology, scoping, documentation, certification, and reporting requirements, and escalate potential alignment issues to the Director.
  • Maintain the annual SOX program calendar, including key planning, walkthrough, testing readiness, deficiency evaluation, remediation, certification, and reporting milestones.
  • Serve as the day-to-day program execution lead, developing governance documents, maintaining program trackers, coordinating deliverables, preparing status materials, and escalating risks, delays, and decision points to the Director, SOX PMO.
  • Drive governance over both business process and IT-dependent controls by promoting adherence to program standards, methodologies, and documentation requirements.
  • Identify opportunities to enhance program effectiveness, efficiency, and scalability through process improvements and automation initiatives.
  • Apply SOX, ICFR, and COSO expertise to guide day-to-day program execution, documentation, and stakeholder decisions.

2. Risk Assessment and Scoping

  • Lead execution of the annual SOX risk assessment process, including analysis of significant accounts, applications, disclosures, financial reporting risks, fraud risks, and changes impacting in-scope processes, systems, reports and third-party service providers, with recommendations prepared for Director review and approval.
  • Evaluate business, operational, and technology changes for potential SOX impacts, including MAR considerations and governance of entity-level controls (ELC).
  • Govern SOX content and change control within the GRC platform by developing and maintaining program standards, reviewing risk-significant changes and facilitating approval through the SOX PMO governance process.
  • Partner with control owners to help confirm risks, controls, applications, evidence, deficiencies, and remediation plans remain current, accurate, and audit ready.

3. Business Process Controls Execution

Lead reviews of process narratives, flowcharts, and risk-and-control matrices (RCMs) for quality, consistency, and compliance with SOX methodology.

  • Partner and drive follow-through with Finance, Actuarial, Claims, Underwriting, Premium, Reinsurance, Treasury, Tax, Technology, and other functional leaders to strengthen control design and execution.
  • Lead documentation-quality and readiness reviews for financial-close controls, including journal entries, account reconciliations, financial reporting, and disclosure-related controls.
  • Provide guidance and challenge around Management Review Controls (MRCs), evidence standards, precision of review, and documentation quality consistent with PCAOB expectations and industry best practices.
  • Perform quality reviews of SOX documentation, including RCMs, narratives, walkthroughs, control evidence, and issue documentation to promote accuracy, consistency, completeness, and audit readiness.

4. IT Controls and Automated Controls Governance and Execution

  • Coordinate governance over IT General Controls (ITGCs) with technology stakeholders, including logical access, change management, computer operations, and system development lifecycle controls for in-scope systems.
  • Develop and maintain standards for automated application controls, system-generated reports, and Information Produced by the Entity (IPE), including design and documentation adequacy.
  • Govern third-party service provider control considerations, including SOC report reviews, bridge letter monitoring, complementary user entity control evaluation, gap assessment, and remediation tracking.
  • Coordinate with AI Governance and Third-Party Risk Management functions to evaluate control implications arising from cloud technologies, robotic process automation, artificial intelligence, and other emerging technologies.

5. MAR and Statutory Reporting Execution

  • Execute key components of the company’s MAR program and maintain statutory ICFR documentation.
  • Operate MAR as an integrated extension of SOX by leveraging the same control inventory, walkthroughs, and evidence within the GRC platform, while coordinating statutory-specific risk and control assessments where requirements differ from SOX.
  • Maintain complete and accurate lineage within the GRC platform from financial statement account and assertion to risk, control, owner, system or report, evidence, deficiency, and remediation activity.
  • Coordinate quarterly and annual management certification activities, including control owner readiness, evidence completeness, deficiency status, disclosure considerations, and preparation of supporting materials for Director review.
  • Prepare and maintain documentation supporting Management’s Report of Internal Control over Financial Reporting.
  • Conduct SOX impact assessments for changes arising from NAIC and DOI guidance and recommend program enhancements or control framework adjustments, as appropriate.

6. Deficiency Management and Remediation

  • Lead and coordinate deficiency intake, documentation, root-cause analysis, remediation tracking, and retest-readiness activities. Prepare severity, aggregation, disposition, reporting, and stakeholder-communication considerations for Director review and approval, in coordination with Internal Audit and relevant control owners.
  • Partner and constructively challenge control owners to develop outcome-based remediation plans, monitor milestones, and confirm management readiness for retest by Internal Audit.

7. Audit Coordination and Stakeholder Management

Coordinate

Original posting on GEICO's site ↗

Listed on hirly, a job board. hirly is not the employer: GEICO is hiring for this role.

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job